ATT&CKSoftwareIronNetInjector

IronNetInjector

S0581

Tool.View on attack.mitre.org

About this tool

IronNetInjector is a Turla toolchain that utilizes scripts from the open-source IronPython implementation of Python with a .NET injector to drop one or more payloads including ComRAT.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

IronNetInjector can obfuscate variable names, encrypt strings, as well as base64 encode and Rijndael encrypt payloads.

T1036.004
Masquerade Task or Service

IronNetInjector has been disguised as a legitimate service using the name PythonUpdateSrvc.

T1053.005
Scheduled Task

IronNetInjector has used a task XML file named mssch.xml to run an IronPython script when a user logs in or when specific system events are created.

T1055
Process Injection

IronNetInjector can use an IronPython scripts to load a .NET injector to inject a payload into its own or a remote process.

T1055.001
Dynamic-link Library Injection

IronNetInjector has the ability to inject a DLL into running processes, including the IronNetInjector DLL into explorer.exe.

T1057
Process Discovery

IronNetInjector can identify processes via C# methods such as GetProcessesByName and running Tasklist with the Python os.popen function.

T1059.006
Python

IronNetInjector can use IronPython scripts to load payloads with the help of a .NET injector.

T1140
Deobfuscate/Decode Files or Information

IronNetInjector has the ability to decrypt embedded .NET and PE payloads.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit 42 IronNetInjector February 2021 Open source
    Reichel, D. (2021, February 19). IronNetInjector: Turla’s New Malware Loading Tool. Retrieved February 24, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.